/FAQ
Significant Data Fiduciaries and cross-border transfers
How an SDF is designated, its extra duties under rule 13, the annual DPIA and audit, transfers outside India, and the Third Schedule retention periods.
What is a Significant Data Fiduciary?
It is a Data Fiduciary, or a class of them, that the Central Government has notified as significant (section 2(z)). Nothing about size makes you one automatically. The Government may notify on the basis of an assessment of the factors it considers relevant, including the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order (section 10(1)). The list is open, so those six are examples rather than a closed test.
How does a company become a Significant Data Fiduciary?
Only by being notified, after an assessment the Government runs. The Rules show how that assessment is fed: carrying out an assessment for notifying any Data Fiduciary or class as a Significant Data Fiduciary is one of the purposes in the Seventh Schedule, and the authorised person for it is an officer of the Ministry of Electronics and Information Technology designated by the Secretary in charge of that Ministry. Acting through that officer, the Central Government may require any Data Fiduciary or intermediary to furnish the information called for, within the period specified (rule 23(1)). No Data Fiduciary or class has been notified as significant in the official sources this wiki mirrors.
What extra duties does a Significant Data Fiduciary have?
Three, on top of everything a Data Fiduciary already owes. It must appoint a Data Protection Officer who represents it under the Act, is based in India, is an individual responsible to its Board of Directors or similar governing body, and is the point of contact for grievance redressal. It must appoint an independent data auditor to carry out a data audit evaluating its compliance. And it must undertake a periodic Data Protection Impact Assessment, a periodic audit, and such other measures as may be prescribed (section 10(2)). Breach of these additional obligations carries a penalty that "may extend to one hundred and fifty crore rupees" (the Schedule).
How often must a Significant Data Fiduciary run a DPIA and an audit?
Once a year. A Significant Data Fiduciary shall, "once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such", undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the Act and the Rules (rule 13(1)). The clock starts at notification, not at the financial year end. The person carrying out the assessment and the audit must then furnish the Board a report containing the significant observations from both (rule 13(2)). A Data Protection Impact Assessment is defined in the Act as a process describing the rights of Data Principals and the purpose of processing, and assessing and managing the risk to those rights (section 10(2)).
What else does rule 13 require?
Two more things, and the second is the only localisation duty in the whole framework. A Significant Data Fiduciary must observe due diligence to verify that the technical measures it uses, "including algorithmic software", for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data are not likely to pose a risk to the rights of Data Principals (rule 13(3)). And it must ensure that personal data specified by the Central Government, on the recommendation of a committee it constitutes, is processed subject to the restriction that the data and the traffic data pertaining to its flow are not transferred outside India (rule 13(4)). The committee includes officials of the electronics and information technology ministry and may include officials of other Ministries or Departments (rule 13(5)).
Can we transfer personal data outside India?
Yes, subject to two government powers rather than a permission list. The Central Government may, by notification, restrict transfer of personal data by a Data Fiduciary for processing to a country or territory it notifies, and nothing in that section cuts down any other Indian law that gives higher protection or stricter transfer rules (section 16). The Rules add that personal data may be transferred outside India "subject to the restriction that the Data Fiduciary shall meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State" (rule 15). No restricted country and no such order appear in the official sources this wiki mirrors.
Does the DPDP law require data localisation?
Only in one narrow case. There is no general requirement to keep personal data in India. The single localisation duty is rule 13(4), which applies to Significant Data Fiduciaries and only to categories of personal data the Central Government specifies on a committee's recommendation, and it covers both that data and the traffic data pertaining to its flow. Everything else turns on section 16, which is a power to block named destinations, not a rule that data must stay home.
Does the Act apply to data we process for overseas clients?
Largely not, under one exemption. Chapter II other than sections 8(1) and 8(5), the whole of Chapter III on rights and duties, and section 16 on transfers do not apply where "personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India" (section 17(1)). Two duties survive that exemption and they are the important ones: overall responsibility for compliance under section 8(1), and reasonable security safeguards to prevent a personal data breach under section 8(5).
Which companies must erase inactive users' data, and after how long?
Three classes, after three years. Under rule 8(1) and the Third Schedule the duty falls on an e-commerce entity "having not less than two crore registered users in India", an online gaming intermediary "having not less than fifty lakh registered users in India", and a social media intermediary "having not less than two crore registered users in India". It covers all purposes except enabling the Data Principal to access her user account, and enabling her to access a virtual token issued by or on behalf of the Data Fiduciary that is stored on its platform and may be used to get money, goods or services. The period is three years from the date the Data Principal last approached the Data Fiduciary for the specified purpose or exercised her rights, or the commencement of the Rules, whichever is latest.
Do we have to warn people before erasing their data?
Yes, and the notice period is short. "At least forty-eight hours before completion of the time period for erasure of personal data under this rule", the Data Fiduciary must inform the Data Principal that her personal data will be erased when the period ends, unless she logs into her user account, otherwise initiates contact for the performance of the specified purpose, or exercises her rights in relation to the processing (rule 8(2)). Note the separate floor underneath all of this: personal data, associated traffic data and other logs must be retained for at least one year from the date of processing for the purposes in the Seventh Schedule (rule 8(3)).
/MYND · DPDP practice
Have a question about your own situation?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.